Dr Ayo Eso, CEO of 3Consulting, has delivered a powerful message in the wake of the Nigeria Data Protection Commission (NDPC)’s landmark fine against Multichoice Nigeria.
His expert insight reveals that the ₦766 million sanction is not just a financial penalty, but a defining moment for Nigeria’s data protection landscape.
“It is a clear sign to everybody that the regulator in Nigeria — that is, the NDPC — is a lot more active and serious about ensuring data protection is adhered to,” Dr Eso says in an exclusive analysis shared with Technology Times TV.
In what is seen as a watershed for data governance in Nigeria, the NDPC’s action against the local business unit of the South African Pay-TV giant, Multichoice, underscores a regulatory resolve that many once doubted. Dr Eso explains that the fine confirms the data protection regulator’s willingness to take enforcement seriously, a significant shift in a regulatory space where such assertiveness was previously absent.
“It shows that the regulator is going to continually strengthen itself by enforcing regulation and proper data protection ethics and principles,” he says. “It will ensure that companies, both large and small, comply.”
The regulatory awakening
Until now, the data protection landscape in Nigeria has been largely shaped by uncertainty. According to Dr Eso, this uncertainty centred on whether NDPC could or would act decisively to compel compliance from big tech and multinational corporations. The Multichoice fine marks a dramatic shift in perception.
“It shows that the regulator is going to continually strengthen itself by enforcing regulation and proper data protection ethics and principles,” he says. “It will ensure that companies, both large and small, comply.”
The four pillars of the Multichoice Nigeria case
According to NDPC’s statement, the Commission based its enforcement decision on four core pillars. Dr Eso breaks them down as follows:
- User Rights (Data Subject Rights): At the heart of data protection are the rights of the data subject — the individual. This includes how companies obtain consent, manage personal data, and uphold user privacy.
- International Data Transfer: The case raises questions around cross-border data flows. Nigerian law permits international data transfer, but only under strict conditions, including approvals from the NDPC.
- Protection of Non-Client Data: Beyond data belonging to direct subscribers, the regulation also extends to individuals whose data may be indirectly held or processed.
- Third-Party Processing: Companies that subcontract services or work with vendors must ensure that these third parties comply with data protection laws. The responsibility remains with the principal organisation.
Dr Eso stresses that these categories signal far-reaching implications for corporate Nigeria. The days of unchecked data practices are over.
Multichoice Nigeria fined ₦.7 billion for data privacy breaches in landmark NDPC action
How to transfer data legally: Two routes
On international data transfers, Dr Eso notes that businesses can approach the NDPC in two ways.
“You must apply,” he says. “Either you request a blanket approval to regularly transfer data or you apply each time a data transfer is needed.”
These agreements, he explains, are common under global data privacy laws. Whichever option a company chooses, reaching out to the regulator is non-negotiable.
“It’s not just a Multichoice problem. Any business transferring data across African borders must comply with each national regulator,” he adds.
The message behind the Multichoice Nigeria fine
Beyond the naira figure, Dr Eso believes that the NDPC is sending a multilayered message to companies.
“Fines send reputational signals,” he says. “They also alert other regulators, both locally and globally, to possible breaches.”
According to him, regulatory enforcement enhances credibility and fosters a culture of accountability.
“We must understand that this isn’t just about money. It shows that the regulator has the reach and the will to enforce compliance,” he adds.
Igniting consumer awareness
Dr Eso sees the Multichoice sanction as a turning point not just for businesses but also for Nigerian consumers.
“People will start asking: What data do you keep on me? Have I consented? Are you sharing my information with third parties?”
He argues that this growing awareness is long overdue. Many Nigerians, he notes, are unaware of their rights as data subjects. But the tide is turning.
“This will spark broader conversations. It will push other service providers to review their practices,” he explains. “Awareness will grow, and that is a good thing for our data economy.”
A call for proactive compliance
In his advisory to businesses, Dr Eso outlines a series of steps to ensure compliance:
- Train staff on data privacy principles
- Conduct regular audits
- Develop clear data protection policies
- Engage vendors and third-party service providers on compliance obligations
“When the regulator comes, it is you they will hold liable, not your third-party provider,” he warns.
Dr Eso adds that compliance should not be reactionary.
“Don’t wait until the NDPC knocks on your door. As long as you hold people’s data, you have a duty to protect it.”
Setting the pace for Africa
Dr Eso points out that Nigeria is quickly becoming a model for other African nations.
“The NDPC recently hosted other data regulators from across Africa. Many of them are now taking cues from Nigeria.”
He suggests that the Multichoice case could trigger similar enforcement actions across the continent.
“We’re setting the standard, particularly for West Africa. Other regulators are watching closely.”
Data Privacy, Cybersecurity and AI: The new triad
In a forward-looking analysis, Dr Eso urges Nigeria’s data professionals to prepare for a convergence of disciplines: data protection, cybersecurity and artificial intelligence.
“We cannot separate the three anymore. Data fuels AI. If the data is not clean, the AI is biased.”
He explains that AI governance is grounded in data ethics — how data is collected, stored, and used. That makes data privacy a foundational requirement.
“Professionals in this space must evolve. If you handle data, you must understand cyber risks and AI implications.”
What comes next?
As Nigeria’s data protection regime gathers steam, Dr Eso says the Multichoice fine should not be seen in isolation.
“This is not just a warning. It’s a blueprint for what is coming.”
He believes Nigeria is laying down a framework that merges local enforcement with global best practices.
“No business is too small. Every company holding personal data must comply. It’s no longer optional.”
A turning point for data protection in Nigeria
The Multichoice Nigeria penalty, in Dr Eso’s view, changes everything. It affirms the NDPC’s capacity to enforce, educates consumers, and challenges businesses to do better.
Nigeria, he insists, is no longer playing catch-up. Instead, it is leading the way in shaping a resilient, rights-based data economy that others in Africa — and beyond — are starting to emulate.
As companies reconsider their data governance policies, one thing is clear: the age of impunity is over. The NDPC has arrived, and it means business.





























Home
